Svmuu News: According to an analysis by BlockSec Phalcon (@Phalcon_xyz), the Aztec Network’s RollupProcessorV3 contract was compromised, resulting in losses exceeding $2.15 million. The root cause lies in the fact that `numRealTxs` was not properly bound to the transaction set enforced by the ZK proof, resulting in a discrepancy between the proof verification path and the L1 settlement logic’s interpretation of the transaction list. The attacker exploited this vulnerability to move real deposits to slots not processed by the settlement logic, bypassing the `decreasePendingDepositBalance()` function. They then created unsecured private balances out of thin air and withdrew them through the normal settlement process, involving a total of seven assets.